PowerSchool hacker sentenced to 4 years in prison

A 19-year-old Massachusetts man who pleaded guilty to hacking the educational technology company PowerSchool was sentenced to four years in prison on Tuesday.

Matthew Lane, who demanded a ransom of $2.9 million from PowerSchool in exchange for not leaking personal data belonging to more than 70 million people, also was ordered to pay about $14 million in restitution and a $25,000 fine, according to court filings.

The hack and its aftermath cost PowerSchool more than $14 million, including the expense of identity theft monitoring for victims. Prosecutors had sought a seven-year sentence. 

Prosecutors told the judge that Lane acted out of greed and had a long history of hacking.

Personal data, including Social Security numbers, special education status and medical conditions for more than 60 million students and 9 million teachers, were exposed in the hack, which became public in January.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

 

Total
0
Shares
Previous Post

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion

Next Post

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

Related Posts

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign

Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusing Google Cloud's Application Integration service to distribute emails. The activity, Check Point said, takes advantage of the trust associated with Google Cloud infrastructure to send the messages from a legitimate email address ("
Read More

⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More

The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer than anyone wants to admit. This week’s stories share one pattern. Nothing flashy. No single moment. Just steady abuse of trust — updates, extensions,
Read More